Home Malware Programs Worms Malware.Imaut

Malware.Imaut

Posted: February 18, 2010

Malware.Imaut is a malicious worm that may represent a security risk for the compromised PC system or its network environment. Malware.Imaut contains characteristics of a rogue antispyware application that uses aggressive and deceptive advertising and false reports of exaggerated system security threats to persuade users to download and purchase their product. Malware.Imaut creates a startup registry entry which produces false security reports to scare the user into purchasing a useless anti-spyware program. Malware.Imaut shows all the signs of a security risk and should be removed from the computer immediately.

Aliases

Worm.Win32.AutoIt.ta (Kaspersky Lab)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %ProgramFiles%\Bifrost\server.exe
    2 %Windir%\server.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\Bifrost][HKEY_LOCAL_MACHINE\SOFTWARE\Bifrost][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9B71D88C-C598-4935-C5D1-43AA4DB90836}]

Related Posts

Loading...